Security Soapbox | Privacy, Security and Everything in Between

This podcast series is brought to you by Lookout. In each episode, host Hank Schless brings on guests from different corners of cybersecurity to discuss the impact various technology trends and events are having on how we think about security and privacy.

5 Minute Friday | A New EU Mandate Makes iOS Less Secure

In this week's episode of 5 Minute Friday, we discuss the new Digital Markets Act (DMA) in the EU and its potential impact on iOS security. We talk through the possible security risks and malware threats that could come from opening iOS devices to third-party app stores. To keep up to date on current threats: ⁠www.lookout.com/threat-intelligence --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

03-22
06:32

5 Minute Friday | CryptoChameleon

In this week’s episode of 5 Minute Friday, we discuss Lookout's discovery of CryptoChameleon, an ongoing advanced phishing kit targeting cryptocurrency platforms and the Federal Communications Commission (FCC). We will dive into the tactics used by the attackers, including SMS and voice phishing, and the success of the kit in stealing high-quality data from victims. For an in-depth analysis, visit: www.lookout.com/threat-intelligence/article/cryptochameleon-fcc-phishing-kit Join Lookout's upcoming exclusive threat briefing: www.lookout.com/community/webinars/cryptochameleon-phishing-kit --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

03-01
10:07

5 Minute Friday | BadBazaar: iOS and Android Used to Target Tibetans and Uyghurs

In this week's episode of 5 Minute Friday, we discuss BadBazaar, an iOS & Android surveillanceware by China's APT-15, designed to target Uyghur Muslims. We take a dive into the invasive nature of Chinese "pre-criminal" surveillance and BadBazaar's recent expansion to iOS devices, providing insights into its early development and the evolving landscape of mobile threats. To keep up to date on current threats: www.lookout.com/threat-intelligence --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

01-26
04:38

5 Minute Friday | Critical Vulnerabilities in iOS & Android

In this week's episode of 5 Minute Friday, we discuss three critical vulnerabilities affecting both iOS and Android devices. We also discuss the importance of patching these vulnerabilities, and the modern phishing attack tactics used to exploit them. To keep up to date on current threats: www.lookout.com/threat-intelligence --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

12-08
05:02

Unveiling the Impact of Cyber Poverty with Ramy Houssaini

In this episode, host Hank Schless welcomes back Ramy Houssaini, Chief Cyber & Technology Risk Officer at BNP Paribas and Founding Chair of The Cyber Poverty Line Institute. They explore the concept of 'cyber poverty,' and shed light on the global disparity in cybersecurity resources, highlighting the critical need for inclusive cyber capability building to safeguard individuals and societies worldwide. For more information on the Cyber Poverty Line Institute, visit: www.cyberpovertyline.org For more information on Lookout, visit: www.lookout.com Connect with Ramy Houssaini on LinkedIn here: www.linkedin.com/in/strategicleadership Connect with Hank Schless on LinkedIn here: www.linkedin.com/in/hank-schless --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

12-07
28:52

5 Minute Friday | Robin Banks: A Poster Child for MFA Bypass

In this week's episode of 5 Minute Friday, we discuss the resurgence of the Robin Banks, a phishing-as-a-service kit, and its tactics like MFA bypass. We also discuss related threats such as 0ktapus, showcasing evolving cyber threats and the replication of successful attack methods among different groups. To stay up to date on recent threat intelligence, ⁠⁠click here⁠. --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

11-17
03:32

5 Minute Friday | Dropper as a Service

In this episode of 5 Minute Friday, we discuss droppers, a type of mobile malware that serves as a middleman between a target device and the threat actor's command and control server. Droppers are now being offered as a service, which could enable more advanced malware to get on more devices.  To stay up to date on recent threat intelligence, ⁠click here⁠. --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

11-10
04:36

5 Minute Friday | Arid Viper: The Mobile Malware Threat

In this episode of 5 Minute Friday, we discuss recent research related to the advanced persistent threat (APT) group Arid Viper. Learn about how their tactics for targeting mobile users are exemplary of an attack chain that many cybercriminals use and why it's so effective To stay up to date on recent threat intelligence, click here. --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

11-03
04:29

5 Minute Friday | Unveiling Infamous Chisel, Sandworm, and Deblind

In this episode of Five Minute Friday, we delve into the shadowy world of cyber espionage as we explore Infamous Chisel, Sandworm, and Deblind. Discover how the Russian APT group, Sandworm, known for major international cyberattacks, ventured into mobile surveillance with Infamous Chisel. Learn about Deblind, a system-level Android app that operates with unprecedented privileges, collecting user activity and suppressing security warnings. For more information, visit: www.lookout.com/threat-intelligence/article/russian-sandworm-apt-infamous-chisel-deblind-spyware --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

11-02
04:29

5 Minute Friday | Red Alert-Rocket Alerts: A Malicious Threat Exploiting Societal Disruption

In this episode of Five Minute Friday, we discuss how societal disruption creates opportunities for malicious actors to exploit people's uncertainties. In this case, we examine a recent case where a malicious version of the legitimate mobile app, RedAlert - Rocket Alerts, was distributed, targeting individuals in Israel. To stay protected against these types of mobile threats, click here. --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

11-02
05:03

5 Minute Friday | iLeakage: The Hidden Threat to Your iOS Device

On this week’s episode of 5 Minute Friday, we are discussing a recent iOS vulnerability, iLeakage, that exploits your web browser including opened tabs and login credentials. Learn more about iLeakage and the importance of protecting your mobile device —  the device that goes everywhere you do. For additional resources on protecting your mobile device, visit: www.lookout.com/products/endpoint-security/mobile-endpoint-security --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

11-02
03:46

5 Minute Friday | Scattered Spider, MGM, and Caesars

Caesars Entertainment and MGM resorts were recently breached by a well-known cybercrime group, Scattered Spider. Listen to this week’s 5 Minute Friday to learn about these attacks, how this group operates, and what you can do to avoid your organization being the next target. For a deeper dive, visit: www.lookout.com/documents/threat-reports/us/lookout_tg_scatteredspider.pdf --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

09-14
04:53

Soap Suds: Protect Your Data From Risky Apps Like TikTok

Recent hype around Chinese apps TikTok and Pinduoduo has put a spotlight on the risk surrounding mobile apps. In this quick-fire Soap Suds episode, host Hank Schless discusses the concerns behind these Chinese apps and highlights the reasons why organizations need to keep tabs on mobile apps in general to minimize the risk to their data. For more information on data collection related security threats and how to ban risky apps like TikTok, check out our blog: https://bit.ly/tiktok-podcast --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

04-24
06:23

Data Overload: Edge Computing Augmenting Our Cloud-first World (ft. Said Ouissal/ZEDEDA)

With more devices than humans in our world today, the amount of data being generated is higher than ever, with no sign of slowing down. Enter: edge computing. In this episode, host Hank Schless is joined by Said Ouissal, Founder and CEO at ZEDEDA, to discuss edge computing — from its business applications to the challenges of securing the technology and everything in between. --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

04-10
22:30

Don’t Think Twice, Modern IT is Alright: Top Ways to Modernize Your IT Today (ft. Faz Sadikali, Cloud Insights)

Organizations are making big decisions to implement cloud solutions to boost collaboration and gain competitive advantage. But many aren’t prepared to handle the risks that cloud services introduce. In this episode of Security Soapbox, host Hank Schless talks shop with Faz Sadikali, Founder of Cloud Insights, on how to build secure workstreams and level up IT to reap the benefits of the cloud while ensuring data remains secure. Read Faz's blog about IT modernization here: https://bit.ly/3h3qqlW --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

12-05
20:48

The Sleeping Giant is Waking Up: the State of Mobile Security Today ft. Cile Montgomery/VMware

With the rapid adoption of BYOD and the growing remote workforce, IT and security teams are just catching on to the need for mobile security to protect corporate data and assets. In this episode, host Hank Schless is joined by Cile Montgomery, Product Line Marketing Manager at VMware, to discuss the new risks mobile devices present to organizations and what trends to expect in the next year for mobile security. --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

11-14
17:08

Soap Suds: The Return of SharkBot

SharkBot, a notorious banking trojan, has just resurfaced since it was first spotted in the wild in October 2021. In this newest variation, the malware targets banking credentials through two apps with collectively over 60,000 downloads on Google Play. In this episode, host Hank Schless discusses what you need to know about SharkBot and how to protect yourself and your organization. --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

09-21
06:07

The Twilio Breach and Phishing: Lessons Learned

Twilio, Cloudflare and other organizations reported employees were targeted with a phishing campaign leveraging a kit codenamed 0ktapus. Tune in for this short episode to learn more about the mechanisms behind the phishing campaign and tips for mitigating this threat. To learn more about this breach and how to protect your organization, check out our blog on this topic: https://bit.ly/3cuweCI --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

08-29
06:25

Fast and Furious: How to Tackle Speed and Complexity in Security with Ramy Houssaini (BNP Paribas)

Cybersecurity challenges are moving at cloud speed and leaving legacy approaches in the dust. On this week’s episode, host Hank Schless is joined by Ramy Houssaini, head of privacy and cyber risk at BNP Paribas, to discuss the top security considerations CISOs should be aware of in this rapidly changing security environment. To learn more about what Ramy spoke about, check out Hank's blog on this topic: https://bit.ly/3KtYMsI --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

06-30
16:53

Risky Business: How to Win Over Your Boards of Directors

When pitching to your board of directors, security should be treated like any other business unit. On this week’s Security Soapbox, our host Hank Schless is joined by Paul Simmonds, CEO of the Global Identity Foundation and Former CISO of AstraZeneca, ICI and Motorola Cellular Infrastructure. They discuss how to cut through buzzwords and turn security into a business enabler. Check out Paul’s guest blog on lookout.com to learn more: https://bit.ly/38zFunf --- Send in a voice message: https://podcasters.spotify.com/pod/show/securitysoapbox/message

05-18
18:50

Recommend Channels